Almost every serious conversation about disposing of data-bearing hardware eventually arrives at the same document: NIST Special Publication 800-88, Guidelines for Media Sanitization. It is short, readable and widely cited — and also widely misquoted, usually by vendors describing themselves as “NIST 800-88 certified.”
There is no such certification. NIST publishes a methodology, not a certification scheme. What a vendor can legitimately claim is that their procedures follow it and that they select the appropriate method for each media type. Here is what that actually means.
The three categories
Clear applies logical techniques — typically a verified overwrite — through the device’s standard read and write interface. It defeats recovery using ordinary software tools. It does not defeat laboratory techniques. Clear is appropriate when the media stays inside your organization and the data classification permits it.
Purge applies techniques that render data infeasible to recover even with state-of-the-art laboratory methods. For magnetic media this means degaussing at an appropriate field strength, or a firmware-level sanitize command. For solid state media it means a verified cryptographic erase or block erase. Purge is the threshold for media leaving your control intact.
Destroy physically destroys the media so it cannot be used at all. Shredding, disintegration, incineration. This is the default for high-classification data, and — importantly — the only reliable option for solid state media where a verified purge path is unavailable.
The mistake that matters most
Degaussing does essentially nothing to a solid state drive.
An SSD stores data in flash cells, not magnetically. Running one through a degausser accomplishes nothing beyond, at best, damaging the controller — which is not the same as sanitizing the data, and can actually complicate verification. Any vendor who offers to degauss your SSDs is telling you something important about their technical competence.
The same applies to media with embedded storage that people forget about: multifunction printers, copiers, medical imaging systems, network appliances, and point-of-sale terminals all routinely carry drives that never appear on an IT asset register.
Choosing a method
Work backwards from two questions: what is the data classification, and where does the media go next?
Media staying inside the organization, carrying low-sensitivity data, can generally be cleared. Media leaving your control — sold, donated, returned to a lessor — needs at minimum a verified purge. Media carrying regulated data, or media where a verified purge path does not exist for the device type, should be destroyed.
What the documentation has to show
The method is only half the deliverable. The record is the other half.
Adequate documentation identifies each device individually, by serial number, with the method applied to it and the date. A blanket certificate stating that a pallet was “processed in accordance with NIST 800-88” does not tell an auditor which drive received which treatment — and reconciling against your asset register is precisely what an audit requires.
Ask any prospective vendor to send you a sample certificate and a sample serialized report before you award the work. It takes five minutes and it is the single most reliable way to find out whether their reporting will survive contact with your auditor.
TDR Recycle is NAID AAA certified for information destruction and R2v3 certified for responsible recycling, operating from Arlington, Texas. Ask us for a sample Certificate of Destruction — we send them to organizations still evaluating our competitors.



